Code Execution Vulnerability in Orval Generated JavaScript Clients Affecting Orval Labs
CVE-2026-71865
9.3CRITICAL
What is CVE-2026-71865?
An unsafe encoding issue in Orval allows double quotes in query parameter names to be improperly handled, resulting in attacker-controlled JavaScript being executed when the zod schema module is imported. Versions prior to 8.21.0 are affected, allowing potential code execution in various environments, including development and CI pipelines, which could lead to serious security risks.
Affected Version(s)
orval < 8.21.0
